List of blog posts
RSS
- Chromium: Same Origin Policy bypass within a single site a.k.a. "Google Roulette"
- Another XSS in Google Colaboratory
- Vulnerability in Hangouts Chat: from open redirect to code execution
- XSS in Google Colaboratory + CSP bypass
- Setting arbitrary request headers in Chromium via CRLF injection
- Yet Another Google Caja bypasses hat-trick
- Firefox - Same-Origin Policy bypass (CVE-2015-7188)
- XSS-es in Google Caja
- XSS via file upload - www.google.com (Postini Header Analyzer)
- XSS via window.stop() - Google Safen Up
- XSS via Host header - www.google.com/cse
- So Google sent me a package...
- Facebook and two dots leak
- Google Doodle - XSS (actually response splitting)
- Gmail and Google+ - tale of two XSS-es
- Easter eggs in Google Bug Bounty
- Google Code Playground - Path Traversal
- Getting started